sonarqube

PackFiles & storage

The sonarqube plugin brings SonarQube code quality and security checks into the agent coding loop. It runs analysis after every file edit, scans for bugs and security issues across 40+ languages, and blocks secrets from reaching the LLM before they are sent.

Unavailable. Delivery for this kind is on the roadmap — not serving yet.

Have a SonarQube setup available for the plugin to enforce.

What your AI can do with it

  • Runs SonarQube analysis automatically after every file edit via PostToolUse hooks
  • Enforces 7,000+ code quality and security rules
  • Scans code for issues across 40+ languages
  • Performs agentic analysis inside the coding loop
  • Applies quality gates to edited code
  • Pre-tool secrets scanning blocks 450+ secret patterns from reaching the LLM

Getting started

  1. Have a SonarQube setup available for the plugin to enforce.
  2. Add the sonarqube plugin to the agent's plugin configuration.
  3. Enable the PostToolUse hooks so analysis runs after each file edit.
  4. Enable pre-tool secrets scanning to intercept secrets before they are sent to the LLM.

Signals

GitHub stars
37k
Forks
4k
Last commit
Sep 2026

Questions

What does the sonarqube plugin do?
It enforces SonarQube code quality and security automatically in the agent coding loop, analyzing code after every file edit and scanning for secrets before they reach the LLM.
Which languages does it support?
Analysis and quality gates work across 40+ languages.
How does secrets scanning work?
Pre-tool secrets scanning checks code before tools run and prevents 450+ secret patterns from reaching the LLM.
When does code analysis run?
PostToolUse hooks run SonarQube analysis after every file edit made by the agent.
Advanced
Item type
plugin
Key
anthropics-claude-plugins-official-sonarqube
Source
github.com/anthropics/claude-plugins-official